DPDP Act 2023 for Marketing Agencies in India: What Changes

Under the Digital Personal Data Protection Act, 2023, your client is the data fiduciary for its customers' data and your agency is the data processor. That makes the client liable for what you do, requires a written contract for you to touch the data at all, and turns the passwords, lead sheets and WhatsApp lists sitting in your team's phones into the client's compliance problem. Core obligations bite on 13 May 2027.

Most DPDP explainers are written for banks, hospitals and e-commerce companies. Nobody has written one for the twelve-person agency in Delhi NCR that runs lead ads for a real-estate developer, keeps the developer's Instagram password in a Google Sheet, and downloads a CSV of 1,400 enquiries every Monday. That agency is squarely inside the Act, and its exposure is different from the client's in ways that matter for the contract, the tools and the offboarding checklist. This post is the version I wish someone had handed me. It is not legal advice; it is an operator's reading of the Act and the Rules, with links to the primary text so you can check it.

Who are you under the Act: fiduciary or processor?

The Act uses two roles. The data fiduciary is whoever decides the purpose and means of processing. The data processor is whoever processes personal data on the fiduciary's behalf. The data principal is the person the data is about. Personal data is any data about an individual who is identifiable by or in relation to it, which covers a name, a phone number, an email, a face in a photograph and the mobile number attached to a WhatsApp enquiry.

An agency wears both hats, and the trick is knowing which one you have on:

ActivityWhose dataYour roleWho is on the hook to the Board
Running Meta lead ads and downloading enquiries for a clientThe client's prospectsProcessorThe client, who can recover from you under the contract
Uploading the client's customer list as a custom audienceThe client's customersProcessorThe client
Managing the client's Instagram inbox and replying to DMsThe client's followersProcessorThe client
Posting photos of the client's customers, patients, students or wedding guestsThose individualsProcessorThe client
Collecting leads on your own agency websiteYour prospectsFiduciaryYou
Storing your clients' contact details, credentials and staff recordsClient contacts, your employeesFiduciaryYou
Using a scheduling tool or CRM to do any of the aboveWhatever it holdsThe tool is your sub-processorStill the fiduciary, through you

The distinction is not academic. As a processor the Act does not put direct statutory duties on you; it puts them on the client and makes the client answer for you. As a fiduciary for your own data, the duties are yours directly. Most agencies I know have never thought about the second column at all.

What does the Act actually say about the client-agency relationship?

Three sub-sections of Section 8 do most of the work. I am quoting them because the paraphrases circulating online soften them.

On top of the Act, the Rules add the operational detail. Rule 3 requires the consent notice to be "presented and be understandable independently of any other information", with an itemised description of the personal data and the specific purpose. A consent line buried in a landing page's terms does not qualify. Rule 7 sets the breach clock: affected individuals must be told without delay, and the Data Protection Board gets an initial intimation without delay plus a detailed report within 72 hours; King Stubb & Kasiva walk through the two stages. EY's guide to engaging processors lists the contract terms fiduciaries are now asking for: scope and purpose, audit rights, sub-processor authorisation, confidentiality, breach assistance and deletion.

When does this actually start?

The Act was passed in August 2023 and then sat without rules for over two years. The DPDP Rules, 2025 were notified on 13 November 2025 with an 18-month phase-in, which Sansa Legal lays out as three phases:

Writing this in September 2026, that is eight months. Enterprise clients are not waiting; the addendums are already arriving. The point of moving now is not fear of the Board on day one. It is that the agency which can answer a client's data questionnaire in an afternoon wins the retainer over the one that cannot.

Where does an agency actually touch personal data?

When I audited our own operation, the list was longer than I expected. Go through yours honestly:

  1. Lead forms. Meta lead ads, website forms, landing pages, WhatsApp click-to-chat. Every enquiry is a name and a phone number, collected for a purpose the person was told, or was not.
  2. WhatsApp broadcast lists. The client's customers, exported to a phone that belongs to an account manager, used for festive offers. This is the single most common unconsented processing I see in Indian agencies.
  3. Custom and lookalike audiences. Uploading a customer list to Meta or Google is processing, and it is disclosure to another entity. The customer needs to have been told marketing was a purpose.
  4. Contest and giveaway entrants. Comments, DMs and Google Forms with names and numbers, kept forever "for the next one".
  5. Faces. Customers, patients, students, gym members, wedding guests. We covered the specific case in the wedding-industry post; the principle is that an identifiable photo is personal data and a written usage clause beats a verbal one.
  6. Influencer data. Creator contact details, PAN numbers for payment, bank details. The ASCI post covers disclosure; this is the other half.
  7. Client credentials. Instagram, Facebook, Google Business Profile and ad-account logins. Not personal data in the ordinary sense, but the key to all of the above, and squarely a "reasonable security safeguard" question under Section 8(5).
  8. Your own leads and staff. The enquiry form on your agency site, your team's Aadhaar copies in a Drive folder, your client contacts in a CRM. You are the fiduciary here, and Rule 3 applies to your own form.

The password problem is now a compliance problem

For years the argument against sharing client passwords was operational: accounts get locked, people leave, two-factor codes go to the wrong phone. The password-sharing post made that case. The Act adds a second argument. A shared password in a WhatsApp group is not a reasonable security safeguard by any reading, and when it leads to a breach, Section 8(5) puts the failure on the client while Section 8(1) stops the client from disowning it. The client's lawyer will then read your contract to see whether it lets them recover from you. Assume it does.

The fix is the same one that was already correct: the client stays admin of their own Meta assets, the agency is granted access through Business Manager or through a tool that uses Meta's official API, each teammate has their own login with a role, and access is removed the day a person or a client leaves. That is also what "technical and organisational measures" in Section 8(4) looks like at agency scale.

Agency dashboard showing per-client workspaces and team roles, the access-control layer a marketing agency needs as a data processor under the DPDP Act
Every teammate on their own login with a role, every client in its own workspace, and access that can be revoked in one click when someone leaves. This is what a processor's "reasonable safeguards" look like in practice.

What should an agency actually do before May 2027?

Six things, in the order I would do them. None needs a lawyer for the first pass, though the contract clause deserves one before you standardise it.

  1. Add a data-processing clause to the retainer. What data you receive, for what purpose, that you process only on the client's instructions, the security measures you keep, that you will notify the client of any breach without delay so they can meet the 72-hour report, which sub-processors you use (your scheduling tool, your CRM, your cloud drive), and that you will delete or return everything within a fixed number of days of the retainer ending. Enterprise clients will send their own; having yours ready keeps the negotiation short.
  2. Fix the lead form. Every form you build for a client gets a standalone consent line that says what will be collected, why, and how to withdraw, in plain language and not inside a terms link. If the same lead will also be added to a WhatsApp list, say so. This is Rule 3, and it is also better marketing: people who opted in convert.
  3. Keep a processing register. One sheet per client: which data, from where, stored where, who on the team has access, which tools touch it, when it gets deleted. It takes an hour per client and answers ninety percent of any questionnaire.
  4. Build the offboarding step. Our onboarding checklist has a mirror image now: when a client leaves, revoke access, delete lead exports and audience files, remove them from any group, and send a one-line confirmation that you have done so. Section 8(7)(b) obliges the client to make you do this; do it before they ask.
  5. Write a one-page breach playbook. Who on the team is told, who calls the client, what the client needs from you for their Board report. When a laptop is stolen or a shared drive is exposed, nobody should be working it out on the day.
  6. Read your tools' terms. A scheduling tool, a CRM and a cloud drive are your sub-processors. Know where they store data, whether they will tell you about a breach, and whether you can delete a client's data on request. This is a reasonable question to ask any vendor, including us.

What are the penalties, correctly stated?

You will read "₹250 crore" attached to every DPDP sentence on the internet. The Schedule to the Act is more specific, and quoting it correctly is a small way of showing a client you have actually read the law:

BreachMaximum penalty
Failing to take reasonable security safeguards to prevent a personal data breach (Section 8(5))₹250 crore
Failing to notify the Board and affected individuals of a breach (Section 8(6))₹200 crore
Failing to meet the additional obligations on children's data (Section 9)₹200 crore
Failing to meet the additional obligations of a Significant Data Fiduciary (Section 10)₹150 crore
Breach of any other provision of the Act or the Rules₹50 crore

These are ceilings, imposed by the Board on the fiduciary after considering the nature, gravity and duration of the breach. No Indian agency is going to be fined ₹250 crore. What can realistically happen is that a client is investigated, the investigation finds the breach originated in the agency's shared spreadsheet, and the client invokes the indemnity in the contract you signed without reading. The commercial risk is losing the client and the fee, not the headline number.

This post is an agency operator's reading of the DPDP Act, 2023 and the DPDP Rules, 2025 as of September 2026, with links to the primary text. It is not legal advice. Get your standard data clause reviewed by a lawyer before you put it in every contract.

One last thought. The Act formalises something that was already the deal: the client trusts you with their customers. Most of the checklist above is what a well-run agency did anyway, written down. The tools that make it easy, such as role-based logins, per-client workspaces, an audit trail and a clean way to remove a client, are the same ones that make the agency run better. That is the argument behind the agency management software page, and it was true before the Board existed.

Frequently asked questions

Is a marketing agency a data fiduciary or a data processor under the DPDP Act?

Usually both. When you run lead ads, manage a client's page or handle their customer lists, the client decides the purpose, so the client is the data fiduciary and your agency is the data processor working under Section 8(2). For your own website leads, employee records and client contacts, your agency is the fiduciary.

When does the DPDP Act actually apply to agencies?

The Act passed in August 2023 and the Rules were notified on 13 November 2025 with an 18-month phase-in. The Data Protection Board provisions are already live, consent managers arrive on 13 November 2026, and the core obligations on consent, security, breach reporting and erasure take effect on 13 May 2027.

What is the penalty for a data breach under the DPDP Act?

The Schedule to the Act sets a ceiling of ₹250 crore for failing to take reasonable security safeguards, ₹200 crore for failing to notify the Board and affected people of a breach, and ₹50 crore for most other breaches. These are maximums the Board can impose on the fiduciary, and the fiduciary can recover from a processor under the contract.

Does the DPDP Act stop agencies from running retargeting or lead ads?

No. It requires that the person whose data is used has given consent after a clear, standalone notice, or that the data was given voluntarily for that purpose. The practical change is that the lead form, the WhatsApp opt-in and the customer-list upload each need a purpose the customer was told about, and a way to withdraw.

Role-based access, per-client workspaces, one-click offboarding.

Run every client from one login with team roles, an approval trail and official Meta API publishing, so the safeguards your clients now ask about are already in place. Flat pricing from ₹999/month, 7-day free trial.

Start Free Trial